Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)1.1%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to inject arbitrary FTP commands via unspecified vectors.
ModificadaMedia (4)0.94%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-0463, CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, and…
ModificadaBaja (3.5)0.76%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-2983.
ModificadaMedia (4)0.94%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnerability than CVE-2013-2985, CVE-2013-2987, CVE-2013-3020, CVE-2013-0568, CVE-2013-0475, and…
ModificadaMedia (4)0.84%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to hijack sessions via a modified cookie path.
ModificadaMedia (5)1.4%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
ModificadaMedia (6.5)1.0%—IBM Sterling B2B IntegratorIBM Sterling File Gateway3/7/201316/6/2026
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via vectors involving the RNVisibility page and unspecified screens, a different vulnerability than CVE-2013-0560.
ModificadaBaja (3.5)0.77%—IBM Sterling B2B IntegratorIBM Sterling File Gateway2/7/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling File Gateway 2.2 and Sterling B2B Integrator allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2013-0468.
ModificadaMedia (4.3)0.94%—IBM Sterling B2B IntegratorIBM Sterling File Gateway2/7/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)2.6%—IBM Gentran Integration SuiteIBM Sterling B2B IntegratorIBM Sterling File GatewayIBM Sterling Integrator12/4/201316/6/2026
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
ModificadaMedia (6.8)27%💥 ExploitHoneywell Enterprise Buildings IntegratorHoneywell SymmetreHoneywell Comfortpoint Open Manager Station24/2/201316/6/2026
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML…
ModificadaMedia (4.3)8.7%💥 ExploitWordpress Integrator Project Wordpress Integrator17/11/201216/6/2026
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.
ModificadaBaja (3.5)1.1%—Collectivecolors Taxonomy View Integrator Module19/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages."
ModificadaBaja (3.5)0.87%—Astha Bhatnagar Shindigintegrator31/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the OpenSocial Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for Drupal, allows remote authenticated users, with "create application" privileges, to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.1%—Drupal Shindig-integrator17/10/200816/6/2026
Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws" that are not related to XSS or access control, a different vulnerability than CVE-2008-4596 and CVE-2008-4597.
ModificadaAlta (7.5)1.3%—Drupal Shindig-integrator17/10/200816/6/2026
Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via unspecified vectors.
ModificadaMedia (4.3)1.0%—Drupal Shindig-integrator17/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in generated pages.
ModificadaAlta (9)2.9%💥 ExploitNsoftware Ibiz E-banking Integrator11/4/200816/6/2026
The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from…
ModificadaMedia (4.9)1.0%—Hitachi Cosminexus Application ServerHitachi Cosminexus Collaboration PortalHitachi Cosminexus DeveloperHitachi Cosminexus ERP Integrator+101/8/200716/6/2026
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's…
ModificadaMedia (5)1.2%—Hitachi Cosminexus Component ContainerHitachi Electronic Form WorkflowHitachi Ucosminexus Application ServerHitachi Ucosminexus Developer+33/4/200716/6/2026
Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form…
ModificadaBaja (2.6)1.2%—IE Integrator15/2/200616/6/2026
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and…
ModificadaMedia (5)1.3%—Compaq Microcom Microcom 6000 Access Integrator3/6/199816/6/2026
Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.
Orbitaley — Vulnerabilidades